Velocity Stream LogoVelocity Stream Logo
Back to Insights
Cloud Cost Optimization

The AWS NAT Gateway Cost Trap: How We Saved a Client $12,000/Month

NAT Gateways are the silent killers of AWS bills. A recent client came to us confused as to why their networking costs had eclipsed their actual compute costs. Here is exactly how we debugged the architecture and reduced their networking bill by 60%.

The Symptoms

The client was running a data-heavy EKS cluster in private subnets. They noticed a massive spike in $0.045/GB data processing charges associated with their NAT Gateway, alongside heavy Cross-AZ data transfer costs.

The Architecture Audit

When running workloads in private subnets, any traffic bound for the public internet must be routed through a NAT Gateway. However, what most teams forget is that AWS services (like S3, DynamoDB, and ECR) are technically on the public internet unless you configure VPC Endpoints.

We discovered the client's EKS cluster was pulling massive amounts of data from S3 buckets and pushing heavy logs to CloudWatch. Because they hadn't configured VPC Endpoints, all of this internal AWS traffic was being routed out through the NAT Gateway and back in, incurring massive data processing fees.

The Fix: VPC Endpoints (PrivateLink)

The solution was architecturally straightforward but highly effective. We implemented Gateway VPC Endpoints for S3 and DynamoDB. Gateway endpoints are completely free and route traffic locally within the AWS network, bypassing the NAT Gateway entirely.

# Terraform snippet for S3 Gateway Endpoint
resource "aws_vpc_endpoint" "s3" {
  vpc_id       = aws_vpc.main.id
  service_name = "com.amazonaws.${var.region}.s3"
  
  route_table_ids = [
    aws_route_table.private.id
  ]

  tags = {
    Name = "s3-gateway-endpoint"
  }
}

For other services like CloudWatch, ECR, and Secrets Manager, we deployed Interface VPC Endpoints (AWS PrivateLink). While these carry a small hourly fee, the data transfer cost is significantly cheaper than routing through a NAT Gateway.

The Second Trap: Cross-AZ Traffic

The second issue was their NAT Gateway placement. They had deployed a single NAT Gateway in `us-east-1a`, but their EKS nodes were spread across `us-east-1a`, `1b`, and `1c`.

When a pod in `1b` needed to reach the internet, it had to cross an Availability Zone to reach the NAT Gateway in `1a`. AWS charges for Cross-AZ traffic. We modified their Terraform configuration to deploy one NAT Gateway per Availability Zone, ensuring traffic stays local to the AZ before egressing.

The Result: 60% Cost Reduction

By implementing VPC Endpoints and optimizing Cross-AZ routing, we dropped their networking bill from $20,000/month to $8,000/month, instantly saving the company $144,000 annually.

Request an Architecture Audit
Chat with an Engineer